CVE-2025-40186 | Linux Kernel up to 6.17.3 tcp lib/refcount.c reqsk_fastopen_remove use after free (Nessus ID 276782 / WID-SEC-2025-2595)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.3. This impacts the function reqsk_fastopen_remove in the library lib/refcount.c of the component tcp. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2025-40186. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.